TCLBANKER is a Brazilian banking trojan for Windows assessed as a major evolution of the Maverick and SORVEPOTEL malware lineage. It targets dozens of banking, fintech, and cryptocurrency platforms, with victim validation and geofencing focused on Brazil. The malware is delivered through a trojanized installer that abuses a legitimate signed Logitech application for DLL sideloading, allowing a malicious loader to execute under the cover of trusted software.
Its loader incorporates extensive anti-analysis and defense-evasion measures, including debugger and virtual-machine checks, environment-dependent payload decryption, telemetry suppression, and removal of user-mode security hooks. After validating that the host matches the expected Brazilian environment, TCLBANKER deploys a banking trojan component and a worm-like propagation component. The banking module establishes persistence, profiles the victim system, monitors browser activity for visits to targeted financial services, and activates operator-controlled fraud workflows when a match is detected.
A defining feature of TCLBANKER is its use of convincing full-screen overlays to harvest credentials, PINs, and other authentication data. These overlays imitate legitimate banking prompts, support workflows, progress screens, and operating-system update dialogs while restricting user interaction and hindering screen capture. Reported operator capabilities also include keylogging, screenshot capture, screen streaming, clipboard manipulation, shell command execution, process and window management, and remote mouse and keyboard control.
TCLBANKER also includes self-propagating modules that abuse trusted victim accounts for further distribution. One module hijacks authenticated WhatsApp Web sessions and automates message sending to contacts, while another uses Microsoft Outlook COM automation to harvest contacts and send phishing emails from the victim’s own mailbox. This combination of banking fraud, remote-control functionality, and worm-like propagation makes TCLBANKER notable within the Latin American banking malware ecosystem. Activity associated with TCLBANKER has been tracked as REF3076, and the malware has been linked to Brazilian cybercrime operations targeting banking and cryptocurrency users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
the banking trojan ... proceeds to establish persistence using a scheduled task
The capabilities given to the operators include: ... Shell command execution ...
enabling the operator to perform a broad range of tasks - Run shell commands
The observed infection chain bundles a malicious MSI installer inside a ZIP file. These MSI installer packages are abusing a signed Logitech program called Logi AI Prompt Builder.
Before it fully unpacks, it checks whether the computer is running in a security sandbox. It looks for debugging tools, virtual machines, and specific antivirus software.
It also checks the system language and time zone to ensure the victim is actually located in Brazil. If the environment does not match a real Brazilian user, the payload refuses to decrypt.
enabling the operator to perform a broad range of tasks - Manage files and processes Enumerate running processes
it beacons out to an external server with an HTTP POST request containing basic system information
enabling the operator to perform a broad range of tasks - Manage files and processes Enumerate running processes List visible windows
Before it fully unpacks, it checks whether the computer is running in a security sandbox. It looks for debugging tools, virtual machines, and specific antivirus software.
a URL monitor that extracts the current URL from the foreground browser's address bar using UI Automation
The user is forced to enter their security codes or personal identification numbers directly into the hacker’s fake screen.
enabling the operator to perform a broad range of tasks - ... Launch a keylogger
enabling the operator to perform a broad range of tasks - Capture screenshots Start/stop screen streaming
enabling the operator to perform a broad range of tasks - Manipulate clipboard
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan family targeting banking and cryptocurrency users in Brazil, using self-propagation, evasion, and MaaS-style distribution.
Android banking trojan family targeting banking and cryptocurrency users in Brazil, using self-propagation, evasion, and MaaS-style distribution.
Named in the malware/tools list as a RAT; no further detail is provided in the content.
Brazilian banking trojan that uses DLL side-loading via a legitimate signed Logitech application to load a malicious component, performs anti-sandbox and anti-analysis checks, verifies the victim is in Brazil, monitors browsers for targeted banking, fintech, and cryptocurrency sites, and steals credentials/PINs through full-screen phishing overlays. It also includes worm-like propagation through WhatsApp Web session cloning and Microsoft Outlook COM automation, while using Cloudflare Workers and related cloud infrastructure for C2 and file hosting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.